Re: #22
Sam Hartman <[email protected]> Tue, 08 Feb 2005 16:24:52 -0500
| Newsgroups | gmane.ietf.kink |
|---|---|
| Message-ID | <[email protected]> |
>>>>> "Michael" == Michael Thomas <[email protected]> writes: Michael> Well, it's pretty simple really: when you get tickets Michael> from the KDC, they aren't protected by PFS so using PFS Michael> later is pretty questionable. It's not useless, but it's Michael> not any huge win either. Until Kerberos itself supports Michael> PFS, people deploying KINK really ought not get worked up Michael> into a lather about turning on PFS to improve security Michael> since it's doesn't to any great degree. I'm confused. I thought the point of PFS was to make it impossible to recover session data . How does the fact that the KDC does not do PFS decrease the value of PFS for Kink?